I'm using dbdata (https://splunkbase.splunk.com/app/4253/) application in order to access my REST endpoint to collect events to splunk.
Here is a sample:
| dbdata url="[Endpoint url]?param1=value1¶m2=value2" headers="[headers data]"
So as far I have several searches, is it possible in splunk to consfigure parametrized constants for url and headers params, so I could reuse them in those searches - kind of searches global config:
| dbdata url=URL_CONSTANT."?param1=value1¶m2=value2" headers=HEADER_CONSTANT
Yes, first create macros called URL_CONSTANT and HEADER_CONSTANT that have your strings, then use it like this:
| eval url = `URL_CONSTANT` . "?param1=value1¶m2=value2", headers=`HEADER_CONSTANT`
| map search="| dbdata url=$url$ headers=headers"
View solution in original post
thanks, macros is the solution here -